Skip to main content

AI Governance

AI Governance in a PIC/S GMP Manufacturer: The ECS Botanics Approach

How a PIC/S GMP-regulated cannabis manufacturer moved from uncontrolled consumer AI tools to a governed, auditable model built on Microsoft 365 Copilot.

Published 2026-09-10QikSolve

ECS Botanics operates as a regulated, pharmaceutical-grade medicinal cannabis manufacturer, subject to PIC/S GMP standards and Organic Drugs Commission (ODC) oversight. Like many regulated manufacturers, the organisation faced a familiar problem: teams were already using consumer generative AI tools such as ChatGPT and Google Gemini for document drafting, data analysis, and process design, alongside an enterprise Microsoft 365 Copilot deployment that had no governing framework around it.

That gap between available capability and controlled use is what an AI governance framework needs to close.

The shadow AI risk

Uncontrolled consumer AI use creates specific, identifiable risks in a GMP environment:

  • no enterprise data governance, audit trail, or change control on the tools being used;
  • outputs that are not version-tracked or linked to the decisions they informed;
  • no record of which tool, model version, or controlled instruction produced an output;
  • potential exposure of confidential product formulations, cultivation data, or manufacturing parameters to consumer services with no contractual data protection.

The mitigation is not to ban AI use — it is to make Microsoft 365 Copilot, already licensed and already enterprise-governed, the sole approved tool for company data, with guardrails that eliminate the risks shadow AI use creates.

A risk-based use-category model

The framework ECS Botanics adopted classifies AI use into three categories, each with different controls and approval authority:

  • Category A — Corporate/non-GMP: Copilot only, human review before external use, no confidential or manufacturing data. Approval: team lead sign-off.
  • Category B — GMP-adjunct: Copilot only, human and qualified-person review before use in a GMP workflow, audit trail of tool/version/output/approver, no direct output in batch records. Approval: qualified person or quality team.
  • Category C — GMP-critical: full ALCOA+ compliance, version-controlled Copilot instances, mandatory QP approval, immutable audit trail, electronic signature capability, formal change control on any model or instruction change. Approval: QA Director and Regulatory Affairs.

Six governance principles

The framework rests on principles that will be familiar to any mature quality system:

  1. Regulated use first — AI use in regulated decisions must support audit readiness, traceability, and data integrity; convenience use is not permitted in GMP workflows.
  2. Human oversight — qualified personnel review and approve AI-generated outputs before use.
  3. Auditability — every AI-supported regulatory decision creates an immutable audit trail linking user, timestamp, model version, inputs, outputs, and approval.
  4. Qualified tools — AI tools must be enterprise-managed, with data governance, change management, and model governance controls.
  5. Segregated use — corporate and non-GMP workflows carry lighter controls than GMP-critical operations.
  6. Data classification discipline — public and internal data can go to Copilot freely; confidential and GMP-critical data are restricted to Category B/C workflows with explicit approval, and specific inputs (batch record numbers, patient names, cultivation parameters, formulation details) are never entered into an AI system directly.

Making the audit trail concrete

A Category B or C interaction produces a structured record: timestamp, user, category, tool and model version, the controlled instruction version applied, an input summary, the output generated, the approving qualified person, and a retention period aligned to the organisation's record-keeping requirements. Records are never deleted or edited retroactively — a correction creates a superseding record with a documented reason.

What this buys an inspector

When an ODC or GMP auditor asks how the organisation ensures data integrity in its AI processes, the answer is a documented, risk-based framework with an audit trail, not an informal assurance. The response an ECS Botanics QA lead can give reads simply: "We follow a risk-based approach. AI in administrative workflows is lighter-touch. AI in GMP workflows requires full ALCOA+ controls, qualified-person review, and an immutable audit trail. We do not use consumer AI tools for company data."

That is the practical shape of AI governance in a GMP environment: not a parallel compliance regime, but the same risk-based, evidence-led discipline already applied to every other quality process, extended to a new category of tool.